Privacy & Data Protection

Student Data Privacy

Last updated: 10 September 2026

Pupil data on Classroom and School plans

This page explains what pupil data SeatPlan.io holds when a teacher or school uses it for classroom seating, what it never asks for, and how long it is kept. It supplements our Privacy Policy, the Classroom and School plan terms and the Data Processing Agreement.

1. Who this covers and who is responsible

  • On a School plan, the school (or district or trust) is the data controller. In the United States the school designates us as a "school official" under FERPA, acting under its direct control.
  • On a Classroom plan bought by an individual teacher, that teacher is the controller for their own class.
  • In both cases ZNZ Systems Ltd (SeatPlan.io) is the processor. We process pupil data only to provide the service and only on the controller's instructions.

2. What pupil data the product holds

A class roster in SeatPlan contains, for each pupil:

  • a name or display name and class membership;
  • the assigned seat;
  • optional tags, notes and keep-apart or sit-together rules that the teacher records.

What we do not ask for, because no classroom feature needs it (please do not enter it):

  • no pupil email address;
  • no date of birth;
  • no photographs;
  • no student login. Pupils never hold accounts and never sign in.

3. FERPA (US schools)

Pupil names and seating assignments are education records under FERPA when a school enters them. We meet the "school official" exception in 34 CFR 99.31(a)(1)(i)(B): we perform a service the school would otherwise do with its own staff, we are under the school's direct control for how the records are used and maintained, we use them only for the purpose the school authorised, and we do not re-disclose them except to the subprocessors listed below. The school official terms are written into section 13 of our Data Processing Agreement.

4. COPPA

SeatPlan.io is not directed to children. Its only users are adults: teachers, school staff and event organisers. We do not collect personal information from children directly, we do not offer a student-facing login, and there is no way for a child to submit information to us through the product. Pupil data reaches us only when an adult enters it on the school's behalf.

5. What appears on printouts

  • The substitute printout shows pupil names and seat positions only. Notes and tags never appear on the substitute printout.
  • Teachers decide who receives a printout. We recommend treating any printed roster as confidential school material.

6. Retention and deletion

  • Class rosters, seating plans, tags and notes are deleted when your plan ends, after the grace period in the Terms of Service, or earlier when you ask. On a School plan, an administrator can run the year-end rollover from Organization settings: it archives every class and deletes the pupil rows by default, keeping room layouts and templates. The administrator can choose to keep the rosters when running it. We send the school a reminder on 1 July each year.
  • You can ask us to delete pupil data at any time. We act on a verified request within 30 days.
  • You can export everything we hold for your account as a machine-readable JSON archive, as described in section 6 of our Privacy Policy.
  • When a plan ends, the retention terms in sections 3 and 9 of the Terms of Service apply.

7. Subprocessors

These are the service providers involved in running SeatPlan.io. Only one of them holds pupil data; the last column says why the others do not.

ProviderPurposeRegionTransfer mechanismPupil data
Amazon Web ServicesHosting, compute, the application database, file storage and the real-time collaboration server.Frankfurt (EU)noneYes
ClerkSign-in and account management for teacher and school staff accounts.United StatesUK IDTA + SCCsNo. Only teachers and school staff hold accounts. Pupils are never account holders, so no pupil data reaches Clerk.
StripePayment processing and invoicing for Classroom and School plans.United StatesUK IDTA + SCCsNo. Stripe receives the billing contact and payment details of the school or teacher, never roster content.
ResendTransactional email such as sign-in links, invoices and collaboration invitations.United StatesUK IDTA + SCCsNo. SeatPlan does not ask for pupil email addresses and schools should not enter them, so school-related email is addressed to teacher and staff accounts only.
PostHogProduct analytics and, with consent, anonymised session replay.United StatesUK IDTA + SCCsNo. Names, guest details and other personal data are stripped before any event is sent, and on-screen text is masked in replays.
SentryError monitoring for the application.Germany (EU)noneNo. Error reports are scrubbed of personal data before they leave our servers and never include roster content.
UpstashRedis for request rate limiting and a short-lived cache of visitor region.Global (multi-region)UK IDTA + SCCsNo. Holds rate-limit counters and region lookups keyed on an anonymised IP address, nothing from a class roster.
Country.isCountry lookup from IP address for regional pricing and consent defaults.Not stated by the providerUK IDTA + SCCsNo. Receives only the visitor's IP address when a page or checkout loads, never roster content.
Amazon BedrockAI extraction of tables and seats from an uploaded floor-plan image or PDF.Frankfurt (EU)noneNo. Only the uploaded floor-plan image or PDF is sent for extraction. Pupil names and class rosters are never part of that upload.

We give schools at least 30 days' notice before adding or replacing a subprocessor that would hold pupil data.

8. Security and staff access

Application data is encrypted in transit and at rest and hosted within Amazon Web Services in the Frankfurt region. Our staff can reach customer data only through an internal console, must record a reason before each access, and every such access is written to an audit record that cannot be edited or deleted. Sections 6 and 7 of the Privacy Policy describe both in detail, and a school may ask for the record of who has accessed its account.

9. Breach notification

If a personal data breach affects your school's data we will notify the school without undue delay, and in any case within 72 hours of confirming the breach, with enough detail for the school to meet its own notification duties.

10. UK schools

  • For schools in the United Kingdom we process pupil data under UK GDPR and the Data Protection Act 2018. The UK addendum in our Data Processing Agreement applies.
  • We can supply the information a school needs to complete the Department for Education data protection toolkit for schools.
  • School plan verification currently matches US schools against the NCES registry. Matching against the DfE Get Information about Schools register (URN) is planned; until then UK schools verify on their school email domain.

11. Contact

Questions about pupil data, or a request to sign a Data Processing Agreement: